Python extractor reports parse errors for files no longer in the scanned commit
還沒有人認領這個 Issue。
評估
研究方向
首先,針對 commit 996e624 重現 Python 擷取器的診斷結果;在該 commit 中,回報的檔案已被刪除,然後將擷取器掃描的檔案集與已簽出的 commit 進行比較。使用 python -m py_compile 作為語法基準。完成的標準是:已接受的檔案不會產生錯誤的解析錯誤,已刪除的檔案不會被回報。
由索引模型根據 Issue 內容生成。
描述
Setup
- CodeQL version: 2.27.0
- Language: Python 3.13
- GitHub default CodeQL analysis (Advanced Security > Code scanning > Default setup)
- Repo (private): https://github.com/lumin-ai/lumin-bot
Observed behavior
CodeQL reports parse errors about two Python files. Here's a log sample (I've replaced my actual filenames with foo.py and bar.py):
Analysis produced the following diagnostic information:
##[group]Could not process some files due to syntax errors (2 results)
* foo.py#L0C0:0: A parse error occurred while processing `foo.py`, and as a result this file could not be analyzed. Check the syntax of the file using the `python -m py_compile` command and correct any invalid syntax.
* bar.py#L0C0:0: A parse error occurred while processing `bar.py`, and as a result this file could not be analyzed. Check the syntax of the file using the `python -m py_compile` command and correct any invalid syntax.
##[endgroup]
What I tried
-
I ran
python -m py_compileon both files. This check completed without errors on Python 3.7, 3.8, 3.9, 3.10, 3.11, and 3.12. -
I removed an old header from the files:
# -*- coding: future_fstrings -*-. This header was a leftover from a Python 2 to Python 3 migration involving https://github.com/asottile-archive/future-fstrings. The warnings stayed. (I imagine, but am not sure, that this header caused the original parsing problem. These two files were the only ones in the repo that still had it.) -
I checked the files for invisible characters and for a byte order mark. The only non-ASCII characters were some bullet characters inside one docstring. I replaced them with ASCII hyphens. The warnings stayed.
-
I replaced the full contents of both files with a single
passstatement. The warnings stayed. -
I deleted both files. The warnings stayed. I believe these logs confirm that CodeQL scanned the commit where I deleted the files (commit 996e624 in pull request 3584):
##[group]Checking out the ref [command]/usr/bin/git checkout --progress --force refs/remotes/pull/3584/head Note: switching to 'refs/remotes/pull/3584/head'. You are in 'detached HEAD' state. You can look around, make experimental changes and commit them, and you can discard any commits you make in this state without impacting any branches by switching back to a branch. If you want to create a new branch to retain commits you create, you may do so (now or later) by using -c with the switch command. Example: git switch -c <new-branch-name> Or undo this operation with: git switch - Turn off this advice by setting config variable advice.detachedHead to false HEAD is now at 996e624 bisect: blow away the whole python modules to see if codeql still complains [skip tests] ##[endgroup]
Expected behavior
- CodeQL must not report parse errors for Python files that
python -m py_compileaccepts. - CodeQL must not report parse errors for files that do not exist in the scanned commit.
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 10 小時
- 30 天內合併 PR
- 134
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
github/codeql 的其他 Issue
-
難度 2/5 1-3 小時 新手友好度 84/100
-
難度 2/5 1-3 小時 新手友好度 82/100
-
難度 2/5 1-3 小時 新手友好度 78/100
-
false-positive
難度 2/5 1-3 小時 新手友好度 70/100
-
false-positive
難度 3/5 1-2 天 新手友好度 68/100
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 74/100
-
難度 1/5 1 小時以內 新手友好度 92/100
-
難度 1/5 1-3 小時 新手友好度 86/100
DavidAnson/markdownlint-cli2#940 ·
-
難度 1/5 1 小時以內 新手友好度 72/100
EclipseFdn/open-vsx.org#13385 · 1 則留言 ·
-
bug ci good first issue
難度 2/5 1-3 小時 新手友好度 88/100